PT-2020-20362 · Google · Asylo

Kang Li

+3

·

Published

2020-08-12

·

Updated

2020-08-13

·

CVE-2020-8905

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Asylo versions prior to 0.6.0
Description A buffer length validation issue allows an attacker to read unauthorized data. The enc untrusted recvfrom function generates a return value deserialized by MessageReader and copied into three extents. The length of the third extents is controlled by external input and not verified on copy, enabling the attacker to force Asylo to copy trusted memory data into a small untrusted buffer.
Recommendations Update Asylo to version 0.6.0 or later.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8905

Affected Products

Asylo